Netskope Threat Labs

HiddenTear

ATP Sandbox Adv. HeuristicsAV

HiddenTear is an open source ransomware that a Turkish programmer released on GitHub as a proof of concept, and cyberattackers used its code in real email phishing attacks. It encrypts a target folder with a locally generated symmetric key and sends that key to a centralized command and control server. Because the source is public and variants remain in active use, detections under this name can reflect many distinct campaigns built from the same code.

First seen
March 2022
Last seen
October 2026
Hiddentear
Alert Name
ByteCode-MSIL.Ransomware.Hiddentear
ByteCode-MSIL.Ransomware.HiddenTear
ByteCode-MSIL.Trojan.HiddenTear
DeepScan:Generic.Ransom.Hiddentear.A.46B461BC
DeepScan:Generic.Ransom.Hiddentear.A.B7AC472B
DeepScan:Generic.Ransom.Hiddentear.A.C6EC6A50
Document-PDF.Ransomware.HiddenTear
Dump:Generic.Ransom.Hiddentear.A.03F09A3A
Dump:Generic.Ransom.Hiddentear.A.095A4810
Dump:Generic.Ransom.Hiddentear.A.44530807